Privacy at Chalkspace.
A short, plain-English version first: we don't sell your data, we don't aggregate it, and we make export & deletion one-click. Below is everything in legal detail.
The short version
- Student PII (names, nicknames, photos, notes, seating data) lives in one tenant per teacher account. It's never shared, sold, or aggregated.
- We never query a school SIS, LMS, or roster provider on your behalf unless you explicitly connect one.
- One-click data export. One-click account deletion. Both available from your profile menu.
- App logs strip PII before storage. Email delivery uses a separate Worker (the only place we hand data to a third party — Resend, our email provider).
- We don't show ads. We don't track you across other sites. We don't use third-party analytics on the auth or app pages.
FERPA & COPPA: Chalkspace operates as a "school official with a legitimate educational interest" under FERPA (20 U.S.C. § 1232g). For K-12 users we treat student records exactly as a teacher would — no disclosure, no redisclosure, no use for any purpose other than the seating-chart service you signed up for.
What data we collect
Account data (you, the teacher)
- Email address, name you choose, and a hashed (PBKDF2-SHA-256, 100k iterations) password
- Account creation timestamp, last-login timestamp
- Billing email & plan info, only if you upgrade to Pro
Student data (your class)
- Names, nicknames, pronouns, free-text notes, color/category tags
- Optional photos only if you upload them
- Per-student rules (front-row, exclusion, neighbor preferences)
- Seating-chart state per period
- Cold-call history & timestamps if you use the random picker
Operational data
- Server logs: HTTP request metadata (IP, user agent, status, latency). Logs are retained on a rolling basis.
- App logs: structured JSON written to Cloudflare's log stream. Student personally identifying information is never included in log output — the app strips student PII before any operational event is recorded.
- Email: transactional only (verification, password reset, billing receipts). Goes via our email Worker; the email provider (Resend) is the only third party that touches your student's email addresses when you import them.
What we do not do
- We do not sell, rent, lease, or share user data with marketers, data brokers, or third-party advertisers.
- We do not aggregate student data across teachers for any purpose.
- We do not train AI models on your data.
- We do not use third-party analytics scripts on auth or in-app pages.
- We do not load tracking pixels, fingerprints, or session-replay tools into the app.
Where the data lives
All app data — your account, your students, your seating charts — is stored in Cloudflare's D1 database, which is a regional SQLite deployment on Cloudflare's edge network. We use the US region by default.
How to take your data out
Export
From Profile → Account → Export data, you can download a JSON archive of every classroom, period, student, rule, and seating layout you have. The export includes timestamps.
Delete
From Profile → Account → Delete account you can permanently remove your account. The deletion is irreversible and propagates to backups within 30 days.
Stop a Pro subscription
From Profile → Billing → Cancel. Your account stays on the free plan afterward, with your existing data intact.
Children's privacy (COPPA)
Chalkspace is not directed at children under 13. Students do not create accounts, do not sign in, and never see Chalkspace unless a teacher uses the optional QR-code student-preferences feature — and in that case they enter their answers on a single-purpose form that doesn't create an account, store an email, or identify them beyond what their teacher already wrote down. We have no way to correlate a student's QR response to any persistent identifier, and we do not.
Data breach notification
If our systems are breached, we'll notify affected users by email within 72 hours of discovery. We'll describe what was accessed, what we're doing, and what you can do. We follow state-by-state notification laws (US, all 50 states) for any breach involving PII.
Changes to this policy
If we make material changes — including adding new categories of data collection or new third parties — we'll email you at least 30 days before they take effect. Non-material changes (typo fixes, clarifications) will be posted at the top of this page with an updated date.
Contact
Privacy questions, deletion requests, and breach disclosures: privacy@chalkspace.win.